← Back

CVE-2005-0588

nvd nist
Published: May 2, 2005Modified: Apr 16, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.

Affected (31)

Products: Mozilla: Firefox, Mozilla
2 products
Firefox
Mozilla
Configuration A
31 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Version 0.10.1
Version 0.10
Version 0.8
Version 0.9.1
Version 0.9.2
Version 0.9.3
Version 0.9
Version 0.9 rc
Version 1.0
Mozilla
Version 1.3
Version 1.4.1
Version 1.4
Version 1.4 alpha
Version 1.5.1
Version 1.5
Version 1.5 alpha
Version 1.5 rc1
Version 1.5 rc2
Version 1.6
Version 1.6 alpha
Version 1.6 beta
Version 1.7.1
Version 1.7.2
Version 1.7.3
Version 1.7.5
Version 1.7
Version 1.7 alpha
Version 1.7 beta
Version 1.7 rc1
Version 1.7 rc2
Version 1.7 rc3

References (18)

Source: secalert@redhat.com
PatchVendor Advisory
Source: secalert@redhat.com
PatchVendor Advisory
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch

Timeline

No history available yet.